T09 · Insecure Skill Coding Practices
- Location
src/douyin/comment-cli.js:151- Finding
Automatic Plaintext Retention of Complete API Results
- Content
View full analysis
- Remediation
View remediation
` or `--save` so data is written only with informed user consent. 3. If persistence is enabled, create files with owner-only permissions: ```js await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, }); ``` 4. Minimize stored data by excluding unnecessary profile identifiers, full comments, runtime metadata, and original request values. 5. Add optional redaction or pseudonymization for usernames, user IDs, and profile URLs. 6. Provide configurable retention and automatic deletion, such as deleting files after a defined number of hours or days. 7. Add a cleanup command and document how to securely remove stored results. 8. Ensure the `logs/` directory is excluded from source control, package publication, crash reports, workspace synchronization, and build artifacts. 9. Clearly disclose the default storage behavior and retention policy in `SKILL.md`, not only in supplementary documentation. ]]>
